Skip to main content

Why Secure Coding is not Enough: Professionals’ Perspective

  • Chapter
ISSE 2009 Securing Electronic Business Processes

Abstract

This paper outlines basic concepts the software community must consider if they are to develop applications and software that is secure. In particular it explains why the common practice of depending on secure coding mechanisms are not enough. Beginning with the drivers for more secure applications and software, and why it is now becoming such an issue, if not a new issue, it examines the problem in terms of why software and applications are delivered without security built in to them and goes on to discuss what we should be doing about it and how we need to go about it, sharing insights that have recently been accumulated by the new and growing community of Certified Secure Software Development Lifecycle professionals.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 84.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  • Paul, Mano CISSP, MCAD, MCSD, Network+, ECSA, Software Assurance Advisor, (ISC) 2 Whitepaper: The Need for Secure Software, (ISC), 2008

    Google Scholar 

  • Paul, Mano CISSP, MCAD, MCSD, Network+, ECSA, Software Assurance Advisor, (ISC) 2 Whitepaper: Ten Best Practices for Secure Software Development

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Norbert Pohlmann Helmut Reimer Wolfgang Schneider

Rights and permissions

Reprints and permissions

Copyright information

© 2010 Vieweg+Teubner | GWV Fachverlage GmbH

About this chapter

Cite this chapter

Colley, J. (2010). Why Secure Coding is not Enough: Professionals’ Perspective. In: Pohlmann, N., Reimer, H., Schneider, W. (eds) ISSE 2009 Securing Electronic Business Processes. Vieweg+Teubner. https://doi.org/10.1007/978-3-8348-9363-5_30

Download citation

  • DOI: https://doi.org/10.1007/978-3-8348-9363-5_30

  • Publisher Name: Vieweg+Teubner

  • Print ISBN: 978-3-8348-0958-2

  • Online ISBN: 978-3-8348-9363-5

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics